· updated 2026-10-07
When you find an account you did not create, the first instinct is to delete it. That is understandable but premature.
What the account tells you
- The creation date is an approximate breach time. Log analysis starts from there.
- The email address often recurs across campaigns and helps identify the toolkit used.
- The last login shows whether access is still active.
Deleting the account destroys all of this, and if the attacker still has another route in, they simply create a new one.
Why one account is never just one account
In the cases we have investigated, a rogue administrator almost always comes with at least one of these:
- a webshell file allowing return without logging in;
- a modified
wp_optionsvalue that recreates the account; - a scheduled WordPress task (cron) that recreates it;
- an added public SSH key on the server.
That is why deleting the account without investigating usually means it is back within a week. More on that in the article about reinfection.